Senior Security Analyst

Bitdefender•San Antonio, TX

About The Position

Our mission at Bitdefender is to reduce risk to customers’ business to allow them to achieve their objectives. We are focused on delivering real security value for an affordable price – no snake oil. To help in this mission, we are looking for a Senior Security Analyst. You will work in a tight knit, experienced team backed up by an international organization that’s been in business for 18 years. The Managed Detection & Response service is a new line of business (think division, business unit, etc). We are an experienced team having built successful Managed Security offerings in the past and staffed by a multitude of cybersecurity organizations and veteran cyber-warfare operators from the military and intelligence services. We all got into this business to provide security services that make customers safer. We must make some money to do that, but our primary goal is to provide services that secure, not just ones that sell. Our team has been around the block together and operate in a 24x7 environment where we manage emergency situations for customers. For this to work, we must trust each other. As a leadership team, we focus on building that trust through accountability, processes and personal relationships. We have plenty of experienced team members with and without families and understand that not all teams can be built outside of work, but we focus on teamwork to build authentic and meaningful engagement. This is a full-time position in a 24/7 operation with a four 10-hour shifting schedule. Scheduled rotations for weekend shifts will be required

Requirements

  • Demonstrate working knowledge and understanding of cybersecurity principles
  • Demonstrate working knowledge and understanding of cyber threats and vulnerabilities
  • Demonstrate working knowledge and understanding of current incident response methodologies
  • Demonstrate working knowledge and understanding of current cyber investigative techniques
  • Demonstrate working knowledge and understanding of current cyber threat trends
  • Demonstrate working knowledge and understanding of computer networking concepts and protocols, and network security methodologies
  • Demonstrate working knowledge and understanding of basic physical computer components and architectures, including the functions of various components and peripherals (e.g., CPUs, NICs, HDDs)
  • Perform analysis of log files from a variety of sources (e.g., individual host logs, network traffic logs, firewall logs, and intrusion detection system [IDS] logs) to identify possible threats to network security
  • Demonstrate working knowledge and understanding of basic system administration, network, and operating system hardening techniques
  • Demonstrate working knowledge and understanding of identifying, modifying, and manipulating applicable system components within Windows, Unix, or Linux (e.g., passwords, user accounts, files)
  • Conduct research, analysis, and correlation across a wide variety of all source data sets (indications and warnings)
  • Demonstrate working knowledge and understanding of defense-in-depth principles and practices (e.g., defense-in-multiple places, layered defenses, security robustness)
  • Demonstrate working knowledge and understanding of virtualization and cloud computing
  • Demonstrate working knowledge and understanding of which system files (e.g., log files, registry files, configuration files) contain relevant information and where to find those system files
  • Demonstrate working knowledge and understanding of hacking methodologies
  • Demonstrate working knowledge and understanding of networking protocols (e.g., TCP/IP), services (e.g., web, mail, DNS), and how they interact to provide network communications
  • Demonstrate working knowledge and understanding of encryption algorithms (e.g., Internet Protocol Security [IPSEC], Advanced Encryption Standard [AES], Generic Routing Encapsulation [GRE], Internet Key Exchange [IKE], Message Digest Algorithm [MD5], Secure Hash Algorithm [SHA]) and how they are used
  • Demonstrate working knowledge and understanding of how to perform packet-level analysis using appropriate tools (e.g., Wireshark, tcpdump)
  • Demonstrate working knowledge and understanding of Security Information and Event Management (SIEM) tools - Searching, aggregating, and correlating data
  • Demonstrate working knowledge and understanding of Web Application Firewall (WAF)
  • Demonstrate working knowledge and understanding of Regular Expressions (Regex)

Responsibilities

  • Serve as an escalation point for security events from multiple sources
  • Using the Cyber Kill Chain, indicators of activity and indicators of compromise with current intelligence information to proactively review customers environments searching for anomalous behavior across network, host and logs data
  • Lead an Incident Response Team to investigate and remediate active threats while accurately documenting results using standard incident response techniques
  • Develop analytic signatures to identify suspicious and malicious behaviors
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service